<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UFW Access to WinEventLogs in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/UFW-Access-to-WinEventLogs/m-p/750181#M29603</link>
    <description>&lt;P&gt;This is a new installation.&lt;BR /&gt;So, no, no Windows Security events onboarded in the past.&lt;BR /&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Mon, 21 Jul 2025 15:40:53 GMT</pubDate>
    <dc:creator>tsocyberoperati</dc:creator>
    <dc:date>2025-07-21T15:40:53Z</dc:date>
    <item>
      <title>UFW Access to WinEventLogs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/UFW-Access-to-WinEventLogs/m-p/750175#M29601</link>
      <description>&lt;P&gt;Hello All,&lt;BR /&gt;&lt;BR /&gt;We have a Splunk Universal Forwarder 9.4.0 (then 9.4.3) installed on a Windows 2022 box to which we don't have direct access.&lt;BR /&gt;We have deployed some apps and the forwarder manages to send us its splunkd.log and some other monitor inputs but we are not able to get the WinEvents (Applications/System/Security) using the specific stanzas.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The host is more hardened that usual,&amp;nbsp; but the Admins managed to configure what they believe are the EventLog permissions, to no avail. Something like this, never happened to us.&lt;BR /&gt;&lt;BR /&gt;We tried updating the agent version and configuring the installation both with LOCAL System permissions and Virtual Account permissions, but still no success.&lt;/P&gt;&lt;P&gt;We don't see any relevant internal info regarding some problem with Permissions or EventLog access.&amp;nbsp;&lt;/P&gt;&lt;P&gt;- is there any event we should look for on Windows Logs or UFW logs to undertand this problem?&lt;BR /&gt;- Is there anything we can activate in the UFW to get more info about this limitation?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 15:05:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/UFW-Access-to-WinEventLogs/m-p/750175#M29601</guid>
      <dc:creator>tsocyberoperati</dc:creator>
      <dc:date>2025-07-21T15:05:23Z</dc:date>
    </item>
    <item>
      <title>Re: UFW Access to WinEventLogs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/UFW-Access-to-WinEventLogs/m-p/750179#M29602</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/34498"&gt;@tsocyberoperati&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;Has this forwarder ever successfully onboarded Windows &lt;STRONG&gt;Security&lt;/STRONG&gt; events into Splunk in the past?&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 21 Jul 2025 15:28:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/UFW-Access-to-WinEventLogs/m-p/750179#M29602</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-07-21T15:28:17Z</dc:date>
    </item>
    <item>
      <title>Re: UFW Access to WinEventLogs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/UFW-Access-to-WinEventLogs/m-p/750181#M29603</link>
      <description>&lt;P&gt;This is a new installation.&lt;BR /&gt;So, no, no Windows Security events onboarded in the past.&lt;BR /&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 15:40:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/UFW-Access-to-WinEventLogs/m-p/750181#M29603</guid>
      <dc:creator>tsocyberoperati</dc:creator>
      <dc:date>2025-07-21T15:40:53Z</dc:date>
    </item>
    <item>
      <title>Re: UFW Access to WinEventLogs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/UFW-Access-to-WinEventLogs/m-p/750193#M29604</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/34498"&gt;@tsocyberoperati&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;are you seeing any permission related issues on Splunkd.log&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;also check splunk forwarder is running as local user or nt_ user&lt;BR /&gt;&lt;BR /&gt;try running splunk with local user and restart the splunk service&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 18:37:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/UFW-Access-to-WinEventLogs/m-p/750193#M29604</guid>
      <dc:creator>SanjayReddy</dc:creator>
      <dc:date>2025-07-21T18:37:11Z</dc:date>
    </item>
    <item>
      <title>Re: UFW Access to WinEventLogs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/UFW-Access-to-WinEventLogs/m-p/750195#M29605</link>
      <description>&lt;P class="lia-align-justify"&gt;Hello&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Your questions are answered in the original post.&lt;BR /&gt;&lt;BR /&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 19:18:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/UFW-Access-to-WinEventLogs/m-p/750195#M29605</guid>
      <dc:creator>tsocyberoperati</dc:creator>
      <dc:date>2025-07-21T19:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: UFW Access to WinEventLogs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/UFW-Access-to-WinEventLogs/m-p/750198#M29606</link>
      <description>&lt;P&gt;There can be several possible issues probably but since you say that the host has been "additionally hardened" I'd hazard a guess that you have applocker policy preventing unknown/not-whitelisted apps from running. Since the eventlogs are ingested by means of spawning external .exe, if it's not whitelisted, it will fail.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 19:53:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/UFW-Access-to-WinEventLogs/m-p/750198#M29606</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-07-21T19:53:28Z</dc:date>
    </item>
  </channel>
</rss>

